Splunk Search

Splunk Search
Community Activity
chandra61446
I have search below .. |inputlookup biweekly_backup | join type=outer max=0 host [search index=tsm sourcetype="tsm-c...
by chandra61446 New Member in Splunk Search 08-05-2016
0 4
0
4
jwertheim
I'm using the following regular expression: (?<timestamp>:"(\d{1,4}\-\d{1,2}\-\d{1,2}\s\d{1,2}:\d{1,2}:\d{1,2})"|(\d...
by jwertheim Explorer in Splunk Search 08-05-2016
0 9
0
9
atiruval
I have a table and one of the column is for URLs. I want to highlight the URLs in blue color. Please let me know how...
by atiruval New Member in Splunk Search 08-05-2016
0 2
0
2
gabriel_vasseur
With tstats, I can't seem to get access to the original events. Even in "verbose" mode, the "Events" tab contains onl...
by gabriel_vasseur Contributor in Splunk Search 08-05-2016
2 3
2
3
Sukisen1981
I have a timechart with 3 line series: A,B and C Now, I have used series colors in Simple XML to change the colors o...
by Sukisen1981 Champion in Splunk Search 08-04-2016
0 2
0
2
proylea
ok, here is my dilemma I have a lookup table like this: _raw,sourcetype,alertMessage,severity *Reloading repositor...
by proylea Contributor in Splunk Search 08-04-2016
0 7
0
7
ZacEsa
Hi, I'm doing two searches with custom rex extraction of fields. For both searches, I have named all the fields I ext...
by ZacEsa Communicator in Splunk Search 08-04-2016
0 3
0
3
information_sec
I'm trying to find the average time (in weeks) it takes to patch specific network vulnerabilities. I take in data fro...
by information_sec New Member in Splunk Search 08-04-2016
0 3
0
3
dpanych
I have an alert that runs every hour at the half hour mark. So at 1:30, 2:30, etc... When I run the timechart command...
by dpanych Communicator in Splunk Search 08-04-2016
0 1
0
1
ivonnepena
I am trying to create new fields to search across multiple sources. I have two problems: When searching for data of ...
by ivonnepena New Member in Splunk Search 08-04-2016
0 3
0
3
phudinhha
Dear Team, What i am trying to achieve is like this: I have a lookup table with many subnets. I am trying to match t...
by phudinhha Explorer in Splunk Search 08-04-2016
1 4
1
4
janderson19
Hello, I'm working on a search for blackboard that will return users who have failed to log in more than 3 times in ...
by janderson19 Path Finder in Splunk Search 08-04-2016
0 4
0
4
jph11
Currently working on an integration betweek Splunk and RSA Archer eGRC. We are working with the security operations m...
by jph11 New Member in Splunk Search 08-04-2016
0 1
0
1
iatwal
how do I change the colors of my bar chart to red, yellow, and green? Here is my query: index=xyxy env=PROD profile...
by iatwal Path Finder in Splunk Search 08-04-2016
0 1
0
1
dbcase
Hi, I have a table with 3 fields in it MSO (a name field) Trend (a Sparkline) Percentage (numeric) When a user cli...
by dbcase Motivator in Splunk Search 08-04-2016
0 2
0
2
ashishlal82
index=bigfix sourcetype=software | eval Hashes_allow_or_deny = if((sha256_allow_or_deny=="*deny*") OR (md5_allow_or_d...
by ashishlal82 Explorer in Splunk Search 08-04-2016
0 4
0
4
sjoerdcopier
I'm trying to use data from a search in a custom command. source | scrapy url=uri This gives me the following erro...
by sjoerdcopier Explorer in Splunk Search 08-04-2016
1 4
1
4
asarran
Hey Fellow Splunkers I have an issue when searching for similar events that are only unique by one character. Exam...
by asarran Path Finder in Splunk Search 08-04-2016
0 3
0
3
tungntran
Hello, I'm trying to change a value of a field using eval case then do a stats count based on that field. I'm getti...
by tungntran Explorer in Splunk Search 08-04-2016
0 2
0
2
sbattista09
I want to alert based off a current value and if that value increases over a threshold within a set time. I want to ...
by sbattista09 Contributor in Splunk Search 08-04-2016
0 4
0
4
ashishlal82
How can I rename a field name with curly braces attached to it e.g. cxy{} and then compare to a field within a looku...
by ashishlal82 Explorer in Splunk Search 08-04-2016
0 1
0
1
duraij
For example: :Report=99,10,99 In this case value 99 occurred twice in this field, so I need to pick this event and...
by duraij Explorer in Splunk Search 08-04-2016
0 2
0
2
jesabs
I have some events which have a field which is named variable. So the event will be like.. field1="a" field2="b" var...
by jesabs Engager in Splunk Search 08-04-2016
0 2
0
2
Lucas_Henry_
I'm trying to use a regular expression to grab words out of a logfile that begin with "FNR" and are exactly 10 alphan...
by Lucas_Henry_ New Member in Splunk Search 08-04-2016
0 2
0
2
dmcbray
I would like to have iplocation fields added to all events when they're ingested and have verified the lookup works i...
by dmcbray New Member in Splunk Search 08-04-2016
0 3
0
3
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...